CVE-2026-27464 HIGH

CVE-2026-27464: Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCE

Vendor Metabase
Product metabase
Weakness CWE-1336
Published February 21, 2026
Last update February 24, 2026

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase instance, including database access credentials. During testing, it was confirmed that a low-privileged user can extract sensitive information including database credentials, into the email body via template evaluation. This issue has been fixed in versions 0.57.13 and 0.58.7. To workaround this issue, users can disable notifications in their Metabase instance to disallow access to the vulnerable endpoints.

Key dates

02Disclosure timeline

February 21, 2026 CVE published
February 24, 2026 Record updated